poundquerydotinfo,
@poundquerydotinfo@virctuary.com avatar

I am still unsure of what the thing actually implies. Obviously everyone wants to side with the plucky dev against the faceless corp, but I also noticed this:

http://freenginx.org/pipermail/nginx/2024-February/000007.html

Dounin complains, if I'm reading this correctly, that corp sent a advisory about an important bug rather than just wait for a regular release on the regular schedule. The bug was in an experimental part of the web server (namely HTTP3 support) so the solution presumably for end users was to disable that feature on production, which was strictly optional in the real world, it wasn't that the only way to fix it was updated code.

And... I'm not seeing what's wrong with that. Obviously I don't want disclosure of the "Suddenly everyone has to wait for an update because now all the script kiddies know" variety, but otherwise early disclosure is good, correct?

Genuine question, would be curious to know your thoughts.

  • @FoW@netsphere.one avatar
    FoW
  • All
  • Subscribed
  • Moderated
  • Favorites
  • security
  • DreamBathrooms
  • mdbf
  • ethstaker
  • magazineikmin
  • GTA5RPClips
  • rosin
  • thenastyranch
  • Youngstown
  • InstantRegret
  • slotface
  • osvaldo12
  • kavyap
  • khanakhh
  • Durango
  • megavids
  • everett
  • cisconetworking
  • normalnudes
  • tester
  • ngwrru68w68
  • cubers
  • modclub
  • tacticalgear
  • provamag3
  • Leos
  • anitta
  • JUstTest
  • lostlight
  • All magazines